Trusted watchdog method and apparatus for securing program execution
An electronic controller for conducting trusted lightweight e-commerce transactions. A trusted transactional cache and the associated transactional protocol allow e-commerce transactions to be committed to a remote server extremely quickly and with little network overhead. The end-to-end transactions are completed is just a few seconds or less. The invention operates equally well on robust private networks as on unpredictable Internet or wireless networks. The transaction is automatically completed following a temporary communication failure with the central site or following a temporary local controller failure. The invention can advantageously be used in embedded Internet products such as fixed or mobile Internet kiosks, transactional terminals, and Internet Appliances.
1 - 8 . (canceled)
9 . A method of securely executing a software program, comprising the steps of:
retrieving a timeout value and a secret key from an entry in a table;
setting a counter to the timeout value and starting the counter;
receiving a secret key provided by the software program;
determining whether the secret key retrieved from the table matches the secret key received from the software program, and
terminating an execution of the software program if the counter indicates that the timeout value has been exceeded or if the secret key retrieved from the table does not match the secret key received from the software program.
10 . The method of claim 9 , further comprising the step of returning to the retrieving step to retrieve a timeout value and a secret key from a next entry in the table.
11 . The method of claim 9 , further comprising the step of allowing the software program to continue execution if the secret key retrieved from the table matches the secret key received from the software program and the timeout value has not been exceeded.
12 . The method of claim 9 , wherein the secret key retrieved from the table and received from the software program are encrypted and wherein the determining step includes a step of decrypting the secret keys retrieved from the table and received from the software program.
13 . The method of claim 9 , wherein the terminating step includes a step of cutting a power off from and returning power to a hardware executing the software program.
14 . The method of claim 9 , wherein the software program is divided into a plurality of execution sequences, each of the execution sequences being divided by a checkpoint at which the secret key is provided and wherein execution of each execution sequence is contingent upon a timely provision of the secret key at the preceding checkpoint.
15 - 23 . (canceled)